Vulnerabilities > IBM > Tivoli Monitoring > High

DATE CVE VULNERABILITY TITLE RISK
2020-04-23 CVE-2020-4311 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Tivoli Monitoring 6.3.0
IBM Tivoli Monitoring 6.3.0 could allow a local attacker to execute arbitrary code on the system.
local
high complexity
ibm CWE-732
7.0
2020-02-13 CVE-2019-4592 Unspecified vulnerability in IBM Tivoli Monitoring 6.3.0.7.10/6.3.0.7.3
IBM Tivoli Monitoring Service 6.3.0.7.3 through 6.3.0.7.10 could allow an unauthorized user to access and modify operation aspects of the ITM monitoring server possibly leading to an effective denial of service or disabling of the monitoring server.
network
low complexity
ibm
7.5
2018-09-19 CVE-2017-1794 Resource Exhaustion vulnerability in IBM Tivoli Monitoring
IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalation and possible denial of service due to unconstrained memory growth.
network
high complexity
ibm CWE-400
7.5
2017-12-13 CVE-2017-1635 Use After Free vulnerability in IBM Tivoli Monitoring
IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error.
low complexity
ibm CWE-416
8.0
2017-07-17 CVE-2017-1183 SQL Injection vulnerability in IBM Tivoli Monitoring 6.2.2.9/6.2.3.5/6.3.0.7
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used.
high complexity
ibm CWE-89
7.5
2017-07-17 CVE-2017-1182 Unspecified vulnerability in IBM Tivoli Monitoring 6.2.2.9/6.2.3.5/6.3.0.7
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used.
high complexity
ibm
7.5
2017-07-17 CVE-2017-1181 Cleartext Transmission of Sensitive Information vulnerability in IBM Tivoli Monitoring 6.2.2.9/6.2.3.5/6.3.0.7
IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted.
local
high complexity
ibm CWE-319
7.0
2016-12-01 CVE-2016-2946 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM Tivoli Monitoring
Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 before FP2 on Linux and UNIX allows local users to gain privileges via unspecified vectors.
local
low complexity
ibm CWE-119
7.8
2016-01-03 CVE-2015-5003 Command Injection vulnerability in IBM Tivoli Monitoring 6.2.2/6.2.3/6.3.0
The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging Take Action view authority and providing crafted input.
network
high complexity
ibm CWE-77
8.5